← Back to FPL Brain

Privacy Policy

Last updated: 1 May 2026

FPL Brain ("we", "us", "our") is a personal project operated by an individual based in the United Kingdom. This privacy policy explains how we collect, use, store, and protect your personal data when you use our website and services at fplbrain.app.

We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller

The data controller is the individual operating FPL Brain. For data protection enquiries, contact us at: privacy@fplbrain.app

ICO registration number: C1922832

2. What Data We Collect

DataPurposeLegal Basis
NameTo identify you within the beta programConsent
Email addressTo contact you about the beta, send feedback requests, and service communicationsConsent
FPL Team IDTo retrieve your public FPL squad data from the official Premier League API and provide personalised recommendationsConsent + Legitimate interest
Signup timestampTo record when consent was givenLegal obligation (GDPR accountability)
Consent textTo maintain a record of what you consented toLegal obligation (GDPR accountability)

Data we do NOT collect

3. How We Use Your Data

Your personal data is used exclusively for:

We will never sell, rent, or share your personal data with third parties for marketing purposes.

4. Legal Basis for Processing

We process your data based on:

You may withdraw consent at any time (see Section 6).

5. Data Storage and Security

Data retention

Your personal data is retained for the duration of the beta program and for up to 30 days after the program ends, after which it will be deleted unless you have subscribed to a paid plan. Anonymised consent records are retained indefinitely for legal compliance.

6. Your Rights Under UK GDPR

You have the following rights:

How to exercise your rights

You can exercise your rights in two ways:

Manage Your Data

Enter your email address to export or delete your data.

7. Cookies

FPL Brain does not use cookies for tracking, advertising, or analytics. We may use essential session cookies required for the service to function. These do not require consent under UK GDPR as they are strictly necessary.

8. Third-Party Services

FPL Brain retrieves publicly available data from the official Fantasy Premier League API (fantasy.premierleague.com) operated by the Premier League. We are not affiliated with, endorsed by, or connected to the Premier League. We do not share your personal data with the Premier League or any other third party.

Our website is hosted on Railway (railway.app). Railway's privacy policy applies to infrastructure-level data handling.

9. International Transfers

Your data is stored on servers operated by Railway (railway.app). Depending on service configuration, data may be stored in the US or EU. Railway's infrastructure complies with industry-standard security practices. If we become aware that data is being transferred outside the UK/EEA, we will ensure appropriate safeguards (such as Standard Contractual Clauses) are in place.

10. Children

FPL Brain is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it immediately.

11. Changes to This Policy

We may update this privacy policy from time to time. The "last updated" date at the top of this page will be revised accordingly. Material changes will be communicated to registered users via email.

12. Complaints

If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO):